Courseiva
Data Protection →hardMultiple Select

SCS-C02 Data Protection Practice Question

A company is designing a data protection strategy for its Amazon S3 bucket that stores sensitive customer data. The bucket must be encrypted at rest using a customer managed key (CMK) that is stored in AWS KMS. The company also needs to ensure that only authorized users can decrypt objects. Which TWO actions should the company take?

⚠ Common exam trap

SCS-C02 often tests the dual requirement of KMS key policies and IAM policies — candidates may pick only one, forgetting that both must allow the action for access to be granted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the KMS key policy to allow only the authorized IAM roles to use the key

Option B is correct because the KMS key policy is the primary resource-based access control for a customer managed key, so modifying it to allow only the authorized IAM roles to use the key ensures that no other principals can call kms:Decrypt or otherwise use the CMK to access the encrypted S3 objects. Option C is correct because even if the key policy permits a role, the caller still needs an identity-based IAM policy granting kms:Decrypt on that specific CMK, so attaching such a policy to the authorized users is required for them to decrypt the objects. Together, the key policy and the IAM policy satisfy the requirement that only authorized users can decrypt data encrypted with the CMK. Option A does not belong because S3 server-side encryption with KMS does not use encryption context in the s3:GetObject request in the way described, and denying based on encryption context is not the mechanism for restricting decryption to authorized users. Option D does not belong because a VPC endpoint and bucket policy control network/API access to S3, not who can decrypt with the KMS CMK. Option E does not belong because SSE-C uses a customer-provided key rather than a CMK stored in AWS KMS, which contradicts the stated requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a bucket policy that denies s3:GetObject unless the request includes a specific encryption context

    Why it's wrong here

    A bucket policy can restrict which principals can call s3:GetObject, but it does not have a condition key that can evaluate the encryption context of a KMS Envelope Encryption operation. The encryption context is checked by KMS during kms:Decrypt, governed by the key policy and IAM policies on the KMS key, not by S3 resource policies. Denying GetObject without a specific context would either block all encryption contexts or be ineffective, and it would not stop an authorized KMS user from decrypting ciphertext obtained through other means.

  • ✓

    Modify the KMS key policy to allow only the authorized IAM roles to use the key

    Why this is correct

    Modifying the KMS key policy is the correct approach because the key policy is the resource-based policy that directly controls which principals can call kms:Decrypt on the CMK. By explicitly listing only authorized IAM roles as principals with Decrypt permission, you ensure that even if an S3 bucket policy or object ACL grants read access to ciphertext, those roles cannot decrypt it without the key. This is a robust data protection strategy because it combines S3 access control with KMS key-level authorization.

  • ✓

    Attach an IAM policy to the authorized users that grants kms:Decrypt on the CMK

    Why this is correct

    Attaching an IAM policy that grants kms:Decrypt on the specific CMK is another valid way to authorize users, since KMS integrates with IAM to allow identity-based permissions. This works when the KMS key policy delegates permission to the root account (or explicitly allows IAM policies), so the key policy still needs to permit the IAM policy to take effect. It is a correct option, though slightly weaker than a key-policy-only approach because it depends on the interaction between IAM and the key policy.

  • ✗

    Create a VPC endpoint for S3 and use bucket policies to restrict access to the endpoint

    Why it's wrong here

    A VPC endpoint for S3, combined with bucket policy restrictions, confines S3 API operations to traffic coming from your VPC, but it does not alter how objects are encrypted or decrypted. Endpoint policies can limit actions like s3:GetObject, but they do not control kms:Decrypt, which is a separate KMS operation governed by KMS policies. An attacker with KMS key permissions could still decrypt ciphertext from anywhere, and users in the VPC would still need KMS permissions to read plaintext.

  • ✗

    Use SSE-C with a customer-provided key

    Why it's wrong here

    SSE-C encrypts S3 objects using a key that you provide in each request, and S3 discards that key after use; it is not a customer master key stored in AWS KMS. Because the key is not managed by KMS, there is no IAM role or KMS key policy that can centrally grant or revoke decryption permissions across your organization. This option does not meet the requirement of using a CMK in AWS KMS, so it is incorrect for a KMS-centric data protection strategy.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.